Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Anyconnect static IP address with SDI authentication

We use the RSA server to backend our user authentication for our Anyconnect home VPN users. There have been requests to have some of our home users have static IP addresses while on the Anyconnect. I have not been able to find a working example on how to get this to work while using SDI (RSA) authentication.

I have a generic /23 for my user VPN network, let's say 10.1.0.0/23 and I would like to perhaps maintain a block of 32 addresses for the purpose of static assignment. Currently my address assignment is done on the ASA itself through a local pool.

The basic flow of what I'm looking to do is:

StaticUser1 connects and is assigned 10.1.0.1
DynamicUser1 connects and is assigned 10.1.0.33

If a user does not have a static ip address assignment, they will be issued an IP from the local pool.

I guess I'm stumped in figuring out how to get the static IP address assigned to the users that need it, while maintaining the SDI/RSA authentication for all the users.

Any help would be appreciated.

Everyone's tags (5)
1 REPLY

Anyconnect static IP address with SDI authentication

So far I know this can be done on ACS in ACS only we do mentioned how this VPN user should get authenticated.I mean to say frist we create users on ACS box then chose RSA for auth.

Under user attributes you can very well mark option to assign the same user.

Thanks

Ajay

896
Views
0
Helpful
1
Replies